White & Case

Senior Analyst, Cybersecurity and Compliance

White & Case$95K — $115K *
Tampa, FL 33647In-Person
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7+ years in Governance, Risk Management, and Compliance (GRC) focusing on vendor and risk management standards
  • Cybersecurity certifications such as CRISC, CISM, CGEIT, CISA, CISSP are required
  • Familiarity with NIST800/CSF, ISO 27001 standards and regulations
  • Experience with compliance frameworks like SSAE16, SOC1, SOC2, PCI, and NIST-800-53
  • Knowledge of Cloud Security assessments and Secure SDLC
  • Proficiency in Microsoft Office, especially Excel for data manipulation
  • Strong attention to detail and analytical thinking

Responsibilities

  • Enhance and manage the GRC function
  • Conduct internal assessments and audits to validate security controls
  • Mentor junior GRC Analysts to build team capacity
  • Track and ensure completion of remediation actions from audits
  • Support continuous compliance monitoring with security policies
  • Provide compliance expertise across departments
  • Conduct third-party vendor security assessments and assurance activities
  • Create and update compliance documentation and regulatory roadmaps

Benefits

  • Comprehensive medical, dental, and vision insurance
  • Life and disability coverage
  • 401(k) retirement savings plan
  • Vacation time and leave programs, including parental leave
  • Eligible for performance bonuses for exempt roles
Full Job Description
Position Summary

The Senior Analyst, Cybersecurity and Compliance plays a pivotal role in protecting the firm against cybersecurity threats. This position is tasked with identifying, evaluating, and monitoring potential cybersecurity risks. They will collaborate with various teams within the firm to ensure that Governance, Risk Management, and Compliance (GRC) areas such as Audits, Information Security Certifications, and Vendor Management Risks are effectively managed. This includes adhering to industry and cybersecurity standards, as well as client and government regulations.

Furthermore, the Senior Analyst, Cybersecurity and Compliance will guide stakeholders in incorporating appropriate security measures into business operations, system designs, and software development processes. This role is responsible for enhancing and implementing processes that assist in planning remediation strategies to ensure compliance with policies and regulations. By providing valuable insights for risk prioritization, the Analyst will prepare reports that highlight trends, risk levels, and metrics. They will focus on building trust and fostering cross-functional partnerships to elevate awareness and successfully implement cybersecurity controls across the firm.

Duties and Accountabilities

The roles and responsibilities of this job include:
  • Maintain and improve the GRC function
  • Provide support for internal assessments and audits at planned intervals and on an ad hoc basis to evaluate and validate the design and operational effectiveness of technical, and administrative controls to help reduce risk in the organization
  • Mentor junior GRC Analysts on the team
  • Assist with monitoring open audit items from internal audits and external compliance/client/certification audits to ensure completion of remediation activities defined in the agreed action plans and risk treatment plans
  • Support continuous monitoring processes to assess compliance with information security policies and standards, legal and regulatory compliance
  • Provide compliance subject matter expertise support to various departments
  • Assist with conducting third-party vendor information security assessment and ongoing third-party assurance activities
  • Design, manage, and update company's compliance related documentation and reports
  • Create any necessary road maps for regulatory compliance


Qualifications

The qualifications for this job include:
  • 5-7+ years of experience within GRC, specifically vendor & risk management standards and frameworks
  • Possessing any cybersecurity certifications, CRISC, CISM, CGEIT, CISA,CISSP, etc.
  • Possessing an understanding of industry standards, certifications, and regulations including NIST800/CSF, ISO 27001
  • Experience with compliance programs related to SSAE16 SOC1, SOC2, PCI, and/or NIST-800-53
  • Working knowledge in Cloud Security assessments, systems, tools, and web application reviews including Secure SDLC life cycle assessments.
  • Working knowledge of enterprise infrastructure and application monitoring tools.
  • Proficient in Microsoft Office applications; SME in Excel and data manipulation
  • Attention to detail. Clear logical and analytical thinker.
  • Able to prioritize and manage multiple tasks under pressure
  • Good verbal, written and numeric skills
  • Ability to travel or work overtime, as needed


This role reports to
Senior Manager, Security and Business Continuity

Benefits at White & Case

White & Case LLP offers a comprehensive suite of benefit programs to all eligible employees, including medical, dental, and vision insurance, life and disability coverage, 401(k) retirement savings, vacation time, and leave programs (including parental leave). Exempt roles are also performance bonus eligible.

The Firm may modify and amend any job description at any time in its sole discretion. Nothing herein creates a contract of employment or otherwise modifies the at-will nature of employment.

The above is only a general description of the essential duties associated with this position and does not represent an exhaustive or comprehensive list of all duties.

About White & Case

White & Case is a global law firm with over 40 offices in 30 countries. The firm provides legal services in areas such as antitrust, banking, capital markets, corporate and M&A, employment, environmental, intellectual property, international arbitration, litigation, project finance, real estate, restructuring, tax, and white collar. White & Case has worked with clients such as Airbus, Citigroup, Coca-Cola, ExxonMobil, Goldman Sachs, Google, HSBC, JPMorgan Chase, Microsoft, Nestle, Pfizer, and Samsung.
Learn more about White & Case
Industry
Founded
1901

Similar Jobs

More Jobs at White & Case

More Information Technology Jobs

Find similar Senior Analyst, Cybersecurity and Compliance jobs: